← back
CVE-2024-3892

Local code execution vulnerability in Telerik UI for WinForms

CVSS 7.2 HIGHEPSS 0.2%CWE-94
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.2EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
15 May 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →